SecretWolf
For accountants & bookkeepers

Share client logins securely — and prove you did

Practices pass sensitive credentials every day — government gateway logins, payroll access, portal passwords. SecretWolf sends them as encrypted, one-time links under your practice's brand, with an audit trail for GDPR.

One-time links AES-256-GCM Full audit trail Your brand & domain

Why practices choose SecretWolf

A payroll or gateway login reaches your client under your practice's name, and leaves a record you can put straight in the compliance file.

GDPR-minded by design

Secret content is encrypted and hard-deleted on view or expiry — there's nothing left to breach. The audit log keeps metadata only, never the credential itself.

Under your practice's brand

Clients receive links carrying your logo and colours on your own domain — a reassuring, professional handover, not a suspicious-looking email.

Ask clients for credentials, safely

Send a branded, encrypted request form to collect a client's login instead of receiving it in plain email — and keep the intake auditable.

A record for your files

Every send, view and verification is logged with timestamps; export to CSV for your compliance file or the ICO's accountability principle.

Verify the recipient

Require an emailed one-time code before a payroll or gateway login reveals, so only your client can open it.

Set an expiry

Links self-destruct on first view or after a deadline you choose — no sensitive credential sitting in an inbox after year-end.

Questions we hear

Does this help with GDPR?

It's built around data minimisation: secrets are encrypted and destroyed on view or expiry, and the audit log stores only metadata — who and when, never the credential. That gives you an accountability record without retaining the sensitive data.

Do clients need an account to open a secret?

No — they click the link and view it once. You can require a one-time code sent to their email first, which is sensible for gateway or payroll logins.

Can I ask a client to send me a password securely?

Yes. Standing request portals and one-off requests give clients a branded, encrypted form to send you a credential — so it never arrives in plain email.

Is my data kept in the UK?

Yes — SecretWolf runs on UK infrastructure over HTTPS, and one-time secret payloads are hard-deleted on view or expiry.

Send your next client login the safe way

Free to start. Branding, requests and the audit trail come with Team and Business.

Start free